Perform 5-Day Comprehensive Security Review -- 2
Employer not named by the sourceRemote
Cyber SecurityFull StackFreelance and contract gigs
Frontier is not the employer and does not collect applications.
About this role
PHP, Web Security, Testing / QA, MySQL, Mobile App Testing, Encryption, API Testing, Security Auditing · Security Audit – Website & iOS/Android Apps
We are looking for a developer/security specialist to perform a 5-day security review and manual testing of our website, backend and iOS/Android apps.
The work includes:
* Review and test Stripe integration, API keys, webhooks, payments, refunds, chargebacks, MobilePay and Apple Pay. * Review GDPR/security of personal data, access control, encryption, storage and deletion. * Manual review based on OWASP Top 10, including SQL Injection, XSS, CSRF, authentication, authorization and exposed API endpoints. * Test iOS and Android apps, including installation, login, backend communication, payments and data. * Review server/app logs, monitoring, PHP and other system versions. * Identify and report security risks and provide recommendations.
Important requirements:
* All sensitive credentials must be reviewed and, where required, changed/rotated and secured, including API keys, secret keys, webhook secrets, passwords and database credentials. * On Day 1, the freelancer must identify and inform us of all credentials/services that he cannot access and that we need to change or provide access to ourselves. * Access will initially be provided t